๐Ÿ” CVE Alert

CVE-2026-106461

MEDIUM 4.3

Backstage: Incorrect authorization in scaffolder task listing

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by incorrect authorization in scaffolder task listing. An authenticated internal user may be able to view metadata for scaffolder tasks outside the visibility intended by a deployment's permission policy. Stored task secrets are not included in the affected response, and no integrity or availability impact was identified. This issue is fixed in version 4.1.0.

CWE CWE-863
Vendor backstage
Product backstage
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for backstage backstage

Be the first to know when new medium vulnerabilities affecting backstage backstage are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

backstage / backstage
< 1.54.6
@backstage / plugin-scaffolder-backend
< 4.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/backstage/backstage/security/advisories/GHSA-7hfw-grcm-cqm6 github.com: https://github.com/backstage/backstage/commit/0253c50673f2832b0b1e9f73348186434e7bd09e github.com: https://github.com/backstage/backstage/releases/tag/v1.54.6